Courses titled as the job.

Every course ends in an artefact you keep, and teaches the same obligation in two realities: early-stage and SME, and enterprise. Frameworks are the source of the obligation, never the subject of the course.

Concepts you hear but never learned

Sixteen ten-minute lessons, free to every member. 0.25 ALC each, 4 ALCs toward the Foundations Certificate.

Free

Open the series to read every term in full.

Bridge letter

A bridge letter, sometimes called a gap letter, is a short statement from a service organization covering the period between the end of its most recent SOC report and the…

TPR · 10 minutes

CUEC

Complementary user entity controls are the controls a SOC report assumes you, the customer, operate. Every service organization's control objectives depend on some things…

TPR · 10 minutes

Subservice organisation and carve-out

A subservice organization is a vendor of your vendor whose controls matter to the service you receive: the cloud provider the software runs on, the data centre, the…

TPR · 10 minutes

Global Privacy Control (GPC)

Global Privacy Control is a browser signal. When it is switched on, the browser sends a header and exposes a flag on every request saying that the user opts out of the…

PRV · 10 minutes

TCF and consent strings

The Transparency and Consent Framework is an industry standard, maintained by the IAB in Europe, for passing a user's consent choices through the advertising supply…

PRV · 10 minutes

SBOM and VEX

A software bill of materials is a parts list for software: every component, library and dependency in a build, with versions, expressed in a machine-readable format such…

CYB · 10 minutes

Statement of Applicability

The Statement of Applicability is the ISO 27001 document that lists every control in the standard's Annex A, states whether each applies to your organization, gives the…

GRC · 10 minutes

ITGC

IT general controls are the controls over the technology environment that financial and other application controls depend on. Auditors group them into four areas…

AUD · 10 minutes

Legitimate interest and the balancing test

Legitimate interests is one of the six lawful bases for processing personal data under GDPR. It allows processing that is necessary for a genuine interest of the…

PRV · 10 minutes

Article 28 processor terms

Article 28 of GDPR sets the mandatory terms of any contract between a controller and a processor. The contract has to bind the processor to act only on the controller's…

PRV · 10 minutes

Business associate agreement

A business associate agreement is the contract that HIPAA requires between a covered entity, such as a healthcare provider or health plan, and any organization that…

PRV · 10 minutes

Risk acceptance and expiry

Risk acceptance is a decision by someone with the authority to make it that a known risk will not be treated further for now. It is a legitimate outcome of risk…

RSK · 10 minutes

Type I versus Type II

A SOC 2 Type I report describes a service organization's controls and gives an auditor's opinion on whether they are suitably designed at a single point in time. A Type…

TPR · 10 minutes

Data processing agreement versus data protection addendum

Both are abbreviated DPA, and both deal with how a vendor handles personal data, which is why they are confused. A data processing agreement is a standalone contract, or…

PRV · 10 minutes

Suppression list

A suppression list is the set of contacts an organization must not market to: people who unsubscribed, objected, opted out of sale, asked by phone not to be called, or…

PRV · 10 minutes

Population and sample

When an auditor tests a control, they start by defining the population: the complete set of instances in which the control should have operated during the period. Every…

AUD · 10 minutes

Privacy & Data Protection

PRV-201

GDPR in Practice: From Articles to an Operating Program

A 12-month privacy program plan with lawful-basis decisions, DPO determination, Article 30 approach and processor terms.

4.00 ALCs $190 with membership Wave 1
PRV-202

US State Privacy Laws in Practice: CCPA/CPRA and the Rest

An applicability matrix by state and a single opt-out handling standard covering Do Not Sell/Share, GPC signals and sensitive data limits.

3.00 ALCs $145 with membership Wave 1
PRV-203

HIPAA in Practice for HealthTech and Business Associates

A BA obligations checklist, a BAA review guide and a minimum-necessary standard for product teams.

3.00 ALCs $145 with membership Wave 1
PRV-210

Data Subject Rights Operations: GDPR, CCPA and HIPAA Access

A DSAR runbook: intake, identity verification, datastore search, vendor sub-requests, exemptions, SLA clock, response pack and evidence file.

4.00 ALCs $190 with membership Wave 1
PRV-220

Building a Record of Processing and Data Inventory That Survives Audit

A completed RoPA and datastore catalog, with the method for keeping it current after the project ends.

3.00 ALCs $145 with membership Wave 1
PRV-230

Consent and Cookie Management Platforms in Practice

A configured CMP design: tag categorisation, TCF and GPC handling, banner logic by jurisdiction, scan cadence and a cookie policy that matches the site.

3.00 ALCs $145 with membership Wave 1
PRV-240

Privacy in Marketing: Consent, Lists and Campaign Compliance

A marketing consent standard and a list-scrub procedure: opt-in cleansing, suppression against opt-outs and Do Not Sell, consent expiry, purchased and event lists, B2B versus B2C rules across GDPR, PECR, CAN-SPAM and TCPA.

3.00 ALCs Free Free Wave 1
PRV-250

DPIA and PIA: Running One That Changes a Decision

A completed DPIA on a realistic case with mitigations that were actually adopted, plus a screening trigger list.

3.00 ALCs $145 with membership Wave 2
PRV-260

Breach Notification Decisions Under Pressure

A breach decision tree across GDPR 72-hour, HIPAA and US state timelines, risk-of-harm tests, and notification templates for regulators, individuals and customers.

3.00 ALCs $145 with membership Wave 1
PRV-270

Retention and Deletion That Actually Deletes

A retention schedule, legal-hold procedure and a deletion evidence standard covering backups and SaaS.

2.00 ALCs $95 with membership Wave 2
PRV-280

International Transfers: SCCs, Transfer Assessments and the DPF

A transfer register with mechanism per flow and a completed transfer impact assessment.

2.00 ALCs $95 with membership Wave 2

Governance, Risk & Compliance

GRC-201

SOC 2 From the Inside: Scoping, Ownership, Evidence and the Auditor

A scoped engagement plan: TSC selection, control ownership across control, evidence and task, an evidence calendar, and a walkthrough guide.

4.00 ALCs $190 with membership Wave 1
GRC-202

ISO 27001 Implementation, Not Interpretation

A Statement of Applicability, risk treatment plan and internal audit plan ready for Stage 1.

4.00 ALCs $190 with membership Wave 2
GRC-203

Control Mapping and Evidence Reuse Across SOC 2, ISO, NIST CSF and HITRUST

A crosswalk for your control set, with deliberate empty cells documented, and an evidence-reuse register.

3.00 ALCs $145 with membership Wave 1
GRC-210

Policies People Read: Writing, Versioning, Acknowledgement and Training Binding

A policy set with version control, acknowledgement records bound to versions, and the training that satisfies each policy.

3.00 ALCs $145 with membership Wave 1
GRC-220

Evidence Management and Audit Readiness

An audit packet: populations, sample selection, walkthrough notes, evidence index and a gap list with remediation tasks.

3.00 ALCs $145 with membership Wave 1
GRC-230

Internal Controls and SOX for Practitioners

A quarterly attestation cycle: ITGC scope, control owner certification, deficiency register with severity, and the quarter-close report.

3.00 ALCs $145 with membership Wave 2
GRC-240

PCI DSS in Practice: Scoping, SAQs and Compensating Controls

A cardholder data environment scope diagram, SAQ selection rationale and a compensating control worksheet.

2.00 ALCs $95 with membership Wave 2
GRC-250

HITRUST for HealthTech: Self-Assessment to Validated

A HITRUST readiness plan with control inheritance from cloud providers and a self-assessment approach.

2.00 ALCs $95 with membership Wave 3
GRC-260

Running a Security Awareness Program Auditors Accept

A training plan mapped to framework controls, completion evidence design and role-specific modules.

2.00 ALCs $95 with membership Wave 2

Audit & Assurance Operations

AUD-201

Owning a Control: Accountability, Delegation and Follow-Through

A control ownership pack: one accountable owner per control, named performers for each task, a status roll-up your leadership can read, and the escalation path when a task slips.

3.00 ALCs $145 with membership Wave 3
AUD-210

Populations, Completeness and Sampling

A population definition per control with the completeness argument written down, a sample selection method, and the sampling worksheet you hand the auditor.

3.00 ALCs $145 with membership Wave 3
AUD-220

Evidence That Holds: Collection, Freshness and Reuse

An evidence calendar with owners and cadence, a naming and retention convention, and an evidence index mapped to controls across two frameworks.

3.00 ALCs $145 with membership Wave 3
AUD-230

Automated Audit Tests and Continuous Control Monitoring

A test catalogue: what each automated test asserts, its data source, failure handling, and the manual procedure it replaces or supplements.

3.00 ALCs $145 with membership Wave 3
AUD-240

Working With Auditors: Walkthroughs, Questions and Findings

A walkthrough script per control, an auditor question log with agreed answers and owners, and a findings response template with remediation dates.

2.50 ALCs $120 with membership Wave 3
AUD-250

Framework Scope as a Guardrail, Not a Burden

A scope decision record: what is in, what is deliberately out, the justification for each exclusion, and the trigger that would bring it back in.

2.50 ALCs $120 with membership Wave 3
AUD-260

Control Maturity and Status Reporting

A maturity model your organization can defend, control-level status definitions, and the quarterly report that shows movement rather than colour.

2.50 ALCs $120 with membership Wave 3

Third-Party & Supply Chain Risk

TPR-201

Building a Third-Party Risk Program: From Zero and At Scale

A TPRM operating model: tiering criteria, inherent risk questionnaire, assessment depth by tier, and an annual cycle.

4.00 ALCs $190 with membership Wave 1
TPR-210

Reading a SOC 2 Report: Opinion, Scope, Exceptions, CUECs and Subservice Organisations

A SOC report review memo template and a completed review of a real report: what the opinion covers, what it carves out, which exceptions matter to you.

3.00 ALCs $145 with membership Wave 1
TPR-215

Handling CUECs: Turning Complementary User Entity Controls Into Your Own Obligations

A CUEC register: every complementary control from your critical vendors, mapped to an internal control, an owner and evidence.

2.00 ALCs $95 with membership Wave 1
TPR-220

Vendor Due Diligence Questionnaires: SIG, CAIQ, Custom and Scoring

A tiered questionnaire set with partial-credit scoring, evidence requests and a review procedure.

3.00 ALCs $145 with membership Wave 1
TPR-230

Contracting for Risk: DPAs, BAAs, Security Schedules and Right to Audit

A contract clause playbook and a negotiation position sheet by vendor tier.

3.00 ALCs $145 with membership Wave 2
TPR-240

Continuous Vendor Monitoring: Breach Intelligence, Attestation Expiry and Recertification

A monitoring standard: what triggers a reassessment, expiry ladders for SOC reports and DPAs, and an offboarding checklist.

3.00 ALCs $145 with membership Wave 2
TPR-250

Fourth-Party and Concentration Risk

A subprocessor map and a concentration analysis for your critical services.

2.00 ALCs $95 with membership Wave 3
TPR-260

Answering Customer Security Questionnaires: The Other Side of the Table

A questionnaire answer library, a trust center content plan and an evidence-reuse approach for buyer diligence.

3.00 ALCs $145 with membership Wave 1
TPR-270

Regulated Outsourcing: DORA, OCC and FCA Registers in Practice

A material outsourcing register, exit plan template and regulator-ready reporting for ICT third parties.

3.00 ALCs $145 with membership Wave 3